DarkGate has emerged as a versatile malware-as-a-service loader and remote access trojan used by multiple threat actors, including TA577, Ducktail, UNC2975, and UNC5085, with campaigns delivering it through large-scale email waves, fake browser updates, VBScript loaders, MSI installers, and messaging platforms such as Skype and Microsoft Teams. Proofpoint reported one major cluster, dubbed BattleRoyal, using DarkGate in attacks against organizations in the United States and Canada, relying on traffic distribution systems including 404 TDS and Keitaro TDS and abusing malicious .URL files tied to CVE-2023-36025 to bypass Windows SmartScreen protections before later shifting some activity to NetSupport.
Technical analyses describe DarkGate as a mature platform with broad post-compromise capabilities, including reverse shell access, PowerShell execution, keylogging, credential and token theft, hidden VNC remote control, privilege escalation, persistence, file management, and even XMRig-based Monero mining. Researchers said the malware continues to evolve its evasion and execution methods through custom Base64 and XOR-obfuscated configuration data, HTTP POST command-and-control, alternate ports such as 2351 and 9999, dynamic API resolution, parent PID spoofing, APC injection via NtTestAlert, DLL side-loading, AutoIt-based execution, and LOLBAS abuse through extexport.exe, underscoring DarkGate’s ongoing role as a significant cybercrime threat.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
In July 2026, SEKOIA published a technical analysis of DarkGate internals, detailing its obfuscation, command-and-control protocol, persistence, privilege escalation, and evasion techniques.
Trellix published research in May 2026 on the continued evolution of the DarkGate malware-as-a-service offering.
Cisco Talos reported a DarkGate campaign active since the second week of March 2024 that delivered malicious Excel attachments using Remote Template Injection to fetch attacker-hosted content and execute DarkGate in memory. Talos said the campaign primarily targeted U.S. organizations, especially healthcare technologies and telecommunications.
In January 2024, VMRay published a technical analysis of DarkGate's use of compiled and obfuscated AutoIt scripts to execute shellcode via Windows API callbacks including CallWindowProc and EnumWindows. The report also clustered DarkGate samples into four variants dating back to 2018 and shared related indicators of compromise.
In January 2024, S2W published a detailed analysis describing DarkGate as a MaaS malware family sold by RastaFarEye since 2017 and documenting its delivery, persistence, and post-compromise capabilities.
In a November 28, 2023 campaign, BattleRoyal used doubleclick.net redirects to Keitaro TDS, which served a first .URL file that downloaded a second .URL file linked to a NetSupport executable.
In late November to early December 2023, Proofpoint observed BattleRoyal replace DarkGate with NetSupport while keeping similar delivery patterns and evolving to chained .URL files.
On October 19, 2023, an external researcher publicly shared details of the RogueRaticate fake browser update activity cluster later linked by Proofpoint to DarkGate delivery.
On October 2, 2023, Proofpoint identified an early BattleRoyal campaign that chained 404 TDS to Keitaro TDS, delivered a malicious .URL file, and ultimately executed an embedded DarkGate payload via VBS and AutoIt.
Telekom Security publicly hosted a Python-based DarkGate extractor in its malware_analysis GitHub repository, providing recursive unpacking for MSI, CAB, and AutoIt payloads and extraction of DarkGate configuration data and decoded strings. The repository metadata indicates extractor.py was updated by fabian-marquardt on September 26, 2023.
Proofpoint observed the BattleRoyal cluster use DarkGate in at least 20 email campaigns between September and November 2023, targeting organizations mainly in the United States and Canada.
Telekom Security published research titled "Shining some light on the DarkGate loader," providing public technical analysis of the DarkGate loader. This predates the later September 2023 extractor-script publication already captured in the timeline.
Later reporting states DarkGate was not widely used until 2021, when its adoption expanded as the malware gained additional capabilities.
DarkGate was first released in 2018, according to later analysis, and Fortinet published research that year on a new DarkGate cryptocurrency-mining and ransomware campaign.
Proofpoint reported on December 20, 2023 that the newly tracked BattleRoyal cluster had heavily used DarkGate and exploited CVE-2023-36025 before Microsoft publicly disclosed the vulnerability.
After the October 19 public reporting, Proofpoint identified RogueRaticate activity in its telemetry, including DarkGate delivery with GroupID "ADS5" through fake browser updates and Keitaro-filtered infrastructure.
Trend Micro published research on DarkGate being used to open organizations for attack via Skype and Teams, marking another documented 2023 delivery vector for the malware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 228 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
13 references tracked. Mallory keeps watching after this page renders.
blog.sekoia.io
Open sourcetrellix.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceblog.talosintelligence.com
Open sourcegithub.com
Open sourcegithub.security.telekom.com
Open source0xtoxin.github.io
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.